<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Important Security Bug - iOS Arlo App 2.1.2 in Features</title>
    <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127458#M837</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New to the forum and happy owner of an Arlo Q soon to be extended with some wire-free Arlos.&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.arlo.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remember a while back seeing a post (but cannot find it anywhere again) mentionning a serious security flaw allowing to bypass Touch ID login without entering the passwod on the iOS Arlo app 2.1.2 (Released August 1st) giving full access to the online system and the library. This stand with the 2 latest releases of iOS 9.3.3&amp;amp;9.3.4 so definitely app related. Perhaps it wasn't for this version of the app but the problem persists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found it too and is quite easy to figure out and works 100%.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I won't give the steps here for obvious reasons but could a Netgear rep get in touch with me for me to pass on the exact repro steps or if acknowledged and spotted already by the dev team give an ETA for the fix in this thread? This is a major issue!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2016 17:07:15 GMT</pubDate>
    <dc:creator>Dinerve</dc:creator>
    <dc:date>2016-09-27T17:07:15Z</dc:date>
    <item>
      <title>Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127458#M837</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New to the forum and happy owner of an Arlo Q soon to be extended with some wire-free Arlos.&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.arlo.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I remember a while back seeing a post (but cannot find it anywhere again) mentionning a serious security flaw allowing to bypass Touch ID login without entering the passwod on the iOS Arlo app 2.1.2 (Released August 1st) giving full access to the online system and the library. This stand with the 2 latest releases of iOS 9.3.3&amp;amp;9.3.4 so definitely app related. Perhaps it wasn't for this version of the app but the problem persists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found it too and is quite easy to figure out and works 100%.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I won't give the steps here for obvious reasons but could a Netgear rep get in touch with me for me to pass on the exact repro steps or if acknowledged and spotted already by the dev team give an ETA for the fix in this thread? This is a major issue!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 17:07:15 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127458#M837</guid>
      <dc:creator>Dinerve</dc:creator>
      <dc:date>2016-09-27T17:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127740#M838</link>
      <description>&lt;P&gt;Dinerve,&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Feel free to private message me your findings and I will create a case and escalate as necessary.&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;

&lt;P&gt;JamesC&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 16:48:59 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127740#M838</guid>
      <dc:creator>JamesC</dc:creator>
      <dc:date>2016-08-16T16:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127874#M839</link>
      <description>&lt;P&gt;Hey JamesC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for getting back to me, I've PM'd you as requested.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Aug 2016 23:34:20 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1127874#M839</guid>
      <dc:creator>Dinerve</dc:creator>
      <dc:date>2016-08-16T23:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1128205#M840</link>
      <description>&lt;P&gt;Dinerve,&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;Thank you for bringing this to our attention. I have created and escalated a case with the information you have provided.&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;JamesC&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 17:24:56 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1128205#M840</guid>
      <dc:creator>JamesC</dc:creator>
      <dc:date>2016-08-17T17:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1128216#M841</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope it will be adressed in the upcoming 2.1.3 version of the iOS app!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 18:12:23 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1128216#M841</guid>
      <dc:creator>Dinerve</dc:creator>
      <dc:date>2016-08-17T18:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1130720#M842</link>
      <description>&lt;P&gt;So, I was hoping this would be resolved with 2.1.3 but it's not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should I make the video public to gain some traction? I'm sure this was reported before me as well and can't find the thread anymore!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently under iOS someone can log in without your fingerprint or password! This is major both in terms of security AND privacy and needs a quick fix! C'mon guys!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 00:58:22 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1130720#M842</guid>
      <dc:creator>Dinerve</dc:creator>
      <dc:date>2016-08-24T00:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1131028#M843</link>
      <description>&lt;P&gt;Dinerve,&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;This issue is still under investigation by the engineering team. We take security and privacy concerns very seriously and hope to be able to provide a solution quickly.&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;I have requested an update on this and will post again once I have more information.&lt;/P&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;P&gt;JamesC&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 17:39:20 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1131028#M843</guid>
      <dc:creator>JamesC</dc:creator>
      <dc:date>2016-08-24T17:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Important Security Bug - iOS Arlo App 2.1.2</title>
      <link>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1131405#M844</link>
      <description>&lt;P&gt;Thanks JamesC,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking forward to have this addressed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 15:36:26 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Features/Important-Security-Bug-iOS-Arlo-App-2-1-2/m-p/1131405#M844</guid>
      <dc:creator>Dinerve</dc:creator>
      <dc:date>2016-08-25T15:36:26Z</dc:date>
    </item>
  </channel>
</rss>

